Skip to content

RDKEMW-18472: CVE-2025-15467 fix for openssl#444

Closed
KTirumalaSrihari wants to merge 1 commit into
developfrom
RDKEMW-18472
Closed

RDKEMW-18472: CVE-2025-15467 fix for openssl#444
KTirumalaSrihari wants to merge 1 commit into
developfrom
RDKEMW-18472

Conversation

@KTirumalaSrihari
Copy link
Copy Markdown
Contributor

Auto-created by CVE pipeline.\n\n- CVE: CVE-2025-15467\n- Component: openssl\n- JIRA: RDKEMW-18472\n- Workflow run: https://github.com/rdk-common/sslcerts-cpc/actions/runs/26516033052

CVE: CVE-2025-15467
Component: openssl
Patch: CVE-2025-15467_openssl_3.0.15_fix.patch
Bbappend: openssl_3.0.15.bbappend

Auto-committed by CVE pipeline run 26516033052
@KTirumalaSrihari KTirumalaSrihari requested review from a team as code owners May 29, 2026 05:24
Copilot AI review requested due to automatic review settings May 29, 2026 05:24
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Automated CVE pipeline backport adding a single OpenSSL 3.0.15-specific patch for CVE-2025-15467, addressing a missing bounds check in evp_cipher_get_asn1_aead_params() (crypto/evp/evp_lib.c). A new version-specific bbappend wires the patch into SRC_URI; it coexists with the existing wildcard openssl_3.0.%.bbappend.

Changes:

  • Add backport patch fixing CVE-2025-15467 in OpenSSL 3.0.15.
  • Add openssl_3.0.15.bbappend to include the new patch via SRC_URI.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
recipes-connectivity/openssl/openssl/CVE-2025-15467_openssl_3.0.15_fix.patch Backport patch adding IV length bounds check in evp_cipher_get_asn1_aead_params.
recipes-connectivity/openssl/openssl_3.0.15.bbappend New version-specific bbappend prepending FILESEXTRAPATHS and appending the CVE patch to SRC_URI.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@KTirumalaSrihari KTirumalaSrihari deleted the RDKEMW-18472 branch May 29, 2026 10:36
@github-actions github-actions Bot locked and limited conversation to collaborators May 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants